Privacy Notice
Last updated: 20 August 2026
1. Introduction
This privacy notice explains how we collect and process your personal data through your use of our websites firstaidforlife.org.uk, onlinefirstaid.com and firstaidforpets.net, including any information you provide when you book or attend a course, buy a product, create a learning account, sign up to our newsletter, or enter a competition or prize draw.
It also covers the personal data we collect when you attend one of our training courses, whether that course is booked through our websites, through our box office, or directly with our office.
First Aid for Life Limited Partnership (registered in England & Wales, number LP015319) and Firstaidonline Ltd (registered in England & Wales, number 08067073) are the data controllers and are responsible for your personal data. We are referred to as "we", "us" or "our" in this notice.
Broadly, Firstaidonline Ltd is responsible for personal data collected through onlinefirstaid.com and our online courses and e-books, and First Aid for Life Limited Partnership is responsible for personal data relating to our face-to-face and blended training. Where we hold your data jointly, both entities are responsible for it and you may contact either of us using the details below.
Contact details
Email: emma@firstaidforlife.org.uk
Postal address: 74 Ramsden Road, Balham, London SW12 8QZ
Telephone: 020 8675 4036
We have not appointed a Data Protection Officer, as we are not required to do so. Emma Hammett is responsible for privacy matters and is the person to contact using the details above.
It is important that the information we hold about you is accurate and up to date. Please tell us if your personal information changes by emailing us at emma@firstaidforlife.org.uk.
Children
Our websites are not directed at children, and by providing us with your data through our sites you confirm that you are over 13 years of age.
We do train children and young people, usually through schools, youth organisations or family bookings. Where a person under 16 attends one of our courses, we collect their personal data from the booking organisation, parent or carer rather than from the child directly, and we require parental or guardian consent before a person under 16 undertakes a regulated qualification. We keep children's data to the minimum needed to deliver and certificate the training safely.
2. What data we collect about you, why, and on what lawful ground
Personal data means any information capable of identifying an individual. It does not include anonymised data. We may process the following categories of personal data about you.
| Category | What it includes and why we process it | Our lawful ground |
|---|---|---|
| Communication Data | Anything you send us through a contact form, email, text, telephone or social media. We process it to reply to you, to keep records, and to establish, pursue or defend legal claims. | Our legitimate interests — namely to respond to enquiries, keep proper records, and protect our legal position. |
| Customer and Booking Data | Your name, title, billing and delivery address, email address, telephone number, employer or organisation, purchase and booking details, and payment details. We process it to take and fulfil your booking or order, to arrange your course, to take payment and to keep records of the transaction. | Performance of our contract with you, or taking steps at your request before entering into a contract. For debt recovery, our legitimate interests. |
| Training and Certification Data | Your attendance, assessment results, the qualification awarded, certificate number and expiry date, and any course paperwork. We process it to deliver and assess your training, to issue certificates, to meet the requirements of our awarding organisation, and to tell you when your certificate is due to expire. | Performance of our contract with you; compliance with legal and regulatory obligations relating to regulated qualifications; and our legitimate interests in maintaining training records and offering renewals. |
| Health and Accessibility Data (special category data) |
Information you or your organisation give us about a medical condition, disability, learning need, recent bereavement, history of self-injury, or anything else that affects your ability to take part safely in practical training or requires a reasonable adjustment. We process it only to keep you safe, to make reasonable adjustments, and to brief your trainer appropriately. | Our lawful ground is our legitimate interests in delivering training safely. Because this is special category data we additionally rely on your explicit consent, or on the substantial public interest ground of equality of opportunity and making reasonable adjustments for disabled people. |
| User Data | How you use our websites and online learning platform, together with anything you post for publication on our sites. We process it to operate and secure our sites, to maintain back-ups, and to administer our online courses. | Our legitimate interests in properly administering our websites and business. |
| Technical Data | Your IP address, login data, browser type and version, time zone and location setting, operating system, pages viewed and navigation paths, and the length and number of your visits. The source is our analytics tracking. We process it to analyse use of our sites, to protect our business, and to measure the effectiveness of our advertising. | Our legitimate interests in administering and improving our websites, growing our business and deciding our marketing strategy. Where this data is collected using non-essential cookies, we rely on your consent (see our Cookie Policy). |
| Marketing Data | Your preferences for receiving marketing from us and your communication preferences, and your entries to competitions, prize draws and giveaways. | Your consent, or our legitimate interests in direct marketing (see section 4). |
We may also process Aggregated Data derived from your personal data — for example, working out what percentage of visitors use a particular part of our site. This does not identify you and is not personal data. If we combine it with your personal data so that you can be identified, we treat the result as personal data.
Criminal offence data
We do not collect information about criminal convictions or offences from our website visitors or course attendees. We do process criminal records check (DBS) information for our trainers, which is covered by a separate privacy notice provided to them.
Automated decision-making
We use software that automatically organises and prioritises our customer records — for example, flagging when a certificate is approaching expiry so we can offer you a renewal, grouping bookings by organisation, and drafting suggested wording for our own staff to review before they contact you. We also use artificial intelligence tools to help draft and summarise communications internally.
These processes support decisions made by our staff; they do not make decisions about you without human involvement, and they have no legal or similarly significant effect on you. A member of our team reviews any communication before it is sent to you. If you would like to know more about how this works, please email us.
If you do not provide your data
Where we need to collect personal data by law, or under the terms of a contract with you, and you do not provide it when asked, we may not be able to perform that contract — for example, we may be unable to enter you for a regulated qualification without the information our awarding organisation requires. If that happens we will tell you at the time.
Change of purpose
We will only use your personal data for the purpose we collected it for, or for a reasonably compatible purpose. If we need to use it for an unrelated purpose, we will tell you and explain the lawful ground for doing so. We may process your personal data without your knowledge or consent where this is required or permitted by law.
3. How we collect your personal data
- Directly from you — when you fill in a form on our sites, book or buy from us, create a learning account, subscribe to our newsletter, enter a competition, give us feedback, or contact us by post, phone, email or social media.
- From the organisation that booked your place — where your employer, school, nursery or club books training for you, they provide us with your details and any information needed to deliver the course safely.
- From our box office and booking systems — where you book a public course through our ticketing provider, they pass your booking details to us.
- Automatically as you use our sites — we collect Technical Data using cookies, server logs and similar technologies. Please see our Cookie Policy for details.
- From third parties — analytics and advertising providers such as Google, Microsoft and Meta; our payment providers; our reviews provider; and, where relevant, publicly available sources such as an organisation's own website.
4. Marketing communications
You will receive marketing communications from us if you have asked us for information, booked or bought from us, entered a competition or registered for a free resource, and you have not opted out.
Where you are an existing customer, we rely on our legitimate interests in direct marketing, and we will only send you information about training and products similar to those you have already bought from us. In all other cases we rely on your consent.
We will always obtain your express opt-in consent before we share your personal data with any third party for their own marketing purposes.
You can ask us to stop sending you marketing at any time by following the unsubscribe link in any marketing email, or by emailing emma@firstaidforlife.org.uk. Opting out of marketing will not stop us sending you communications that relate to a course or order — for example joining instructions, certificates or receipts.
5. Who we share your personal data with
We share your personal data with the following categories of recipient, all of whom are required to keep it secure and to use it only for the purposes we specify:
- Our trainers — self-employed trainers delivering your course receive the attendee list and any safety or accessibility information they need to teach the course safely.
- Our awarding organisation — see the section on joint controllership below.
- The organisation that booked your training — where your employer, school or club paid for your place, we confirm your attendance and certification to them.
- Our professional advisers — accountants, bookkeepers, lawyers, bankers, auditors and insurers.
- HM Revenue & Customs, regulators and other authorities — where we are required to report or disclose.
- A buyer or successor — if we sell, transfer or merge parts of our business or assets.
We also use service providers who process personal data on our instructions and only for the purposes we specify. They fall into the following categories. We do not store your full card details ourselves — these are handled by our payment providers.
| Category of provider | Where the data is processed |
|---|---|
| Booking and ticketing platforms, through which places on our public courses are sold | United Kingdom |
| Website hosting and e-commerce providers, who run our online shop, online courses and learner accounts | United Kingdom |
| Payment providers, who take and process card and online payments | United Kingdom, EU and United States |
| Customer relationship management and email marketing providers, in which we hold contact records and send emails | United States |
| Cloud storage, email, calendar and productivity providers, in which we hold course schedules, attendee lists and correspondence | United States |
| Providers of the internal systems we use to administer courses and to manage our trainers | United States |
| Artificial intelligence tools, used to help draft and summarise our own communications before a member of our team reviews them | United States |
| Accounting and bookkeeping software providers | United States |
| Website security and anti-spam providers, who help us tell genuine visitors from automated bots | United States |
| Review platforms, through which we invite and display customer reviews | United Kingdom and EU |
| Analytics and advertising providers, where you have consented to non-essential cookies. These are named individually in our Cookie Policy | United States and EU |
If you would like to know the specific companies we use in any of these categories, please email us at emma@firstaidforlife.org.uk and we will tell you.
Our awarding organisation — joint controllers
Where you take a regulated qualification, we are an approved centre of Qualsafe Awards (a trading name of Qualsafe Limited, City View, 3 Wapping Road, Bradford, West Yorkshire BD3 0ED). We transfer your registration and assessment data to Qualsafe so that your qualification can be awarded and your certificate issued.
For that data, we and Qualsafe Awards act as joint data controllers under a Data Management Contract between us. In practice this means:
- we are responsible for collecting your data accurately, for keeping your course and assessment records, and for answering questions about the training you received from us;
- Qualsafe Awards is responsible for registering you, awarding the qualification, issuing and verifying your certificate, and for its own quality assurance and regulatory reporting;
- you may exercise your data protection rights against either of us. If you contact us about data held by Qualsafe, we will pass your request on and tell you we have done so.
Qualsafe Awards retains learner and certification data indefinitely, so that certificates can be verified and replaced long after a course. Their own privacy policy is published at qualsafe.org, and we recommend reading it if you take a regulated qualification with us.
6. International transfers
Some of our service providers are based outside the United Kingdom, which means your personal data may be transferred outside the UK. We are subject to the UK General Data Protection Regulation (UK GDPR), and where we transfer your data outside the UK we make sure one of the following safeguards is in place:
- we transfer to a country the UK government has approved as providing an adequate level of protection for personal data; or
- where we use US-based providers, we transfer to providers certified under the UK–US Data Bridge (the UK Extension to the EU–US Data Privacy Framework); or
- we use contracts approved by the Information Commissioner's Office — the International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses — which give your personal data the same protection it has in the UK.
If none of these safeguards is available, we will ask for your explicit consent to the specific transfer, and you may withdraw that consent at any time. Please email us if you would like more information about the safeguards we use.
7. Data security
We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. We limit access to your personal data to those employees, trainers, contractors and other third parties who have a genuine business need to know it. They process your personal data only on our instructions and are subject to a duty of confidentiality.
We have procedures in place to deal with any suspected personal data breach, and we will notify you and the Information Commissioner's Office of a breach where we are legally required to do so.
8. Data retention
We keep your personal data only for as long as necessary for the purposes we collected it for, including to satisfy any legal, accounting or reporting requirements. In deciding how long to keep data we consider its amount, nature and sensitivity, the potential risk of harm from unauthorised use or disclosure, the purposes for which we process it, whether we can achieve those purposes another way, and what the law requires.
| Type of data | How long we keep it |
|---|---|
| Customer, booking, financial and transaction records | Six years after you stop being a customer, as required for tax purposes. |
| Course and assessment records for regulated qualifications | At least three years, as our awarding organisation requires. Note that Qualsafe Awards, as joint controller, retains its own copy of learner and certification data indefinitely so that certificates can be verified and replaced. |
| Certificate details we hold for renewal purposes — your name, qualification, certificate number and expiry date | Until three years after the certificate expires, so that we can confirm your qualification if you ask and remind you when a renewal is due. You can ask us to stop at any time. |
| Health and accessibility information | Deleted shortly after your course has taken place, unless we need to keep it in connection with an incident or a legal claim. |
| Marketing preferences and consent records | For as long as you remain subscribed, and for a reasonable period afterwards so we can evidence that you opted out. |
| Enquiries that do not lead to a booking | Up to two years from your last contact with us. |
| Website analytics data | As set out in our Cookie Policy. |
In some circumstances we may anonymise your personal data so that it can no longer be associated with you, for research or statistical purposes. We may use anonymised information indefinitely without further notice to you.
9. Your legal rights
Under data protection law you have the right to:
- request access to your personal data;
- request correction of personal data that is inaccurate or incomplete;
- request erasure of your personal data;
- object to our processing of your personal data;
- request restriction of processing of your personal data;
- request the transfer of your personal data to you or to another organisation; and
- withdraw consent at any time, where we are relying on consent as our lawful ground.
You can read more about these rights on the Information Commissioner's Office website at ico.org.uk.
To exercise any of these rights, please email emma@firstaidforlife.org.uk.
You will not have to pay a fee to access your personal data or to exercise any of your other rights. We may charge a reasonable fee, or refuse to comply, if your request is clearly unfounded, repetitive or excessive.
We may need to ask you for specific information to confirm your identity before we act on your request. This is a security measure to make sure personal data is not disclosed to anyone who has no right to receive it. We may also contact you for further information to speed up our response. Where we do so, the time we have to respond is paused until we receive what we have asked for.
When responding to a request to access your personal data, we are only required to carry out searches that are reasonable and proportionate, as recognised by the Data (Use and Access) Act 2025. We take into account the nature of the information you have asked for, the context in which we hold it, the difficulty involved in finding it, and how useful it will be to you.
We aim to respond to all legitimate requests within one month of receiving the request, or of receiving any identity verification or clarification we have asked for. If your request is particularly complex, or you have made several requests, it may take us longer; in that case we may extend the response period by up to a further two months, and we will tell you within one month of your request that we need longer and why.
10. How to complain
If you are unhappy with how we have handled your personal data, please tell us first so that we have the chance to put it right.
You can make a data protection complaint to us by:
- emailing emma@firstaidforlife.org.uk, with "Data protection complaint" in the subject line; or
- writing to us at 74 Ramsden Road, Balham, London SW12 8QZ.
We will acknowledge your complaint within 30 days of receiving it. We will investigate without undue delay, keep you informed of our progress, and explain our conclusion clearly and in enough detail for you to understand how we reached it.
If you are not satisfied with our response, you have the right to complain to the Information Commissioner's Office, the UK supervisory authority for data protection, at ico.org.uk. We would be grateful for the chance to resolve your concerns before you approach the ICO.
11. Third-party links
Our websites may include links to third-party websites, plug-ins and applications. Clicking those links or enabling those connections may allow third parties to collect or share data about you. We do not control these third-party websites and we are not responsible for their privacy statements. When you leave our websites, we encourage you to read the privacy notice of every website you visit.
12. Cookies
Our websites use cookies. You can set your browser to refuse all or some browser cookies, or to alert you when a website sets or accesses cookies. If you disable or refuse cookies, some parts of our websites may become inaccessible or stop working properly.
For full details of the cookies we use, how long they last, and how to change your choices, please see our Cookie Policy.
13. Changes to this notice
We keep this privacy notice under review. Any changes will be posted on this page, and where the changes are significant we will tell you by email. This version replaces all previous privacy policies published on our websites.
Visitor statistics
We count visits to this website using our own privacy-friendly counting system. It places nothing on your device and shares nothing with anyone — we simply count which pages are viewed so we can improve the site. If you would rather not be included in the counts, click here.
